Hacker News new | ask | show | jobs
by ctidd 177 days ago
You want lax for the intuitive behavior on navigation requests from other origins. Because there’s no assumption navigation get requests are safe, strict is available as the assumption-free secure option.